Configuring an ACL for IGMPv2 SSM Mapping

You can use either a standard or extended ACL to identify the group multicast address(es) that you want to add source addresses to when creating an IGMPv2 SSM mapping.

For standard ACLs, you must create an ACL with a permit clause, and the ip-source-address variable must contain the group multicast address. This can be configured directly with a subnet mask or with the host keyword, in which case a subnet mask of all zeros (0.0.0.0) is implied.

For extended ACLs, the ip-source-address variable must contain either 0.0.0.0 or the any keyword. Additionally, the extended ACL must be configured with a permit clause and the host keyword. This can be configured directly with a subnet mask or with the host keyword, in which case a subnet mask of all zeros (0.0.0.0) is implied.

  1. Enter global configuration mode.
    device# configure terminal
  2. In the following example, IPv4 standard access-list 20 is configured for the group multicast address: 239.1.1.1 by including the host keyword.
    device(config)# ip access-list standard 20 
    device(config-std-ipacl-20)# permit host 239.1.1.1
  3. In the following example, a permit statemnet is added to standard access-list 20 for the group multicast address: 224.1.1.0 with a subnet mask of 0.0.0.255.
    device(config)# ip access-list standard 20 
    device(config-std-ipacl-20)# permit 224.1.1.0 0.0.0.225
  4. In the following example, extended access-list 100 is configured for the group multicast address: 232.1.1.1 with a subnet mask of 0.0.0.255.
    device(config)# ip access-list extended 100
    device(config-ext-ipacl-100)# permit ip any host 232.1.1.1

The following example configures two access lists, one standard and one extended, that can be used for SSM mapping.

device(config)# ip access-list standard 20 
device(config-std-ipacl-20)# permit host 239.1.1.1
device(config-std-ipacl-20)# permit 224.1.1.0 0.0.0.225
device(config-std-ipacl-20)# exit
device(config)# ip access-list extended 100
device(config-ext-ipacl-100)# permit ip any host 232.1.1.1